Vice or virtue? Exploring the dichotomy of an offensive security engineer and government “hack back” policies

2Citations
Citations of this article
129Readers
Mendeley users who have this article in their library.

Abstract

In response to increasing cybersecurity threats, government and private agencies have increasingly hired offensive security experts: "red-hat” hackers. They differ from the better-known “white-hat” hackers in applying the methods of cybercriminals against cybercriminals and counter or preemptively attacking, rather than focusing on defending against attacks. Often considered the vigilantes of the hacker ecosystem, they work under the same rules as would be hackers, attackers, hacktivists, organized cybercriminals, and state-sponsored attackers-which can easily lead them into the unethical practices often associated with such groups. Utilizing the virtue (ethics) theory and cyber attribution, we argue that there exists a dichotomy among offensive security engineers, one that appreciates organizational security practices, but at the same time violates ethics in how to retaliate against a malicious attacker.

Cite

CITATION STYLE

APA

Withers, K. L., Parrish, J. L., Smith, J. N., & Ellis, T. J. (2020). Vice or virtue? Exploring the dichotomy of an offensive security engineer and government “hack back” policies. In Proceedings of the Annual Hawaii International Conference on System Sciences (Vol. 2020-January, pp. 1813–1822). IEEE Computer Society. https://doi.org/10.24251/hicss.2020.224

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free